plugin

Gallery Album Vulnerabilities

20 known security issues reported for the Gallery Album WordPress plugin. Most recent disclosed Jan 2, 2025.

2 critical 1 high 6 medium

Running Gallery Album on your site? Check whether your installed version is affected.

Scan your site free

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Jan 2, 2025

CVE-2023-45631 on NVD →

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Jul 6, 2024

CVE-2024-37542 on NVD →

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Jun 8, 2024

CVE-2024-35750 on NVD →

Gallery – Image and Video Gallery with Thumbnails <= 2.0.3 - Authenticated (Contributor+) SQL Injection

critical

The Gallery – Image and Video Gallery with Thumbnails plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...

CVSS:
9.9
Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Jun 6, 2024

CVE-2024-35750 on NVD →

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Reflected XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Mar 31, 2024

CVE-2024-30550 on NVD →

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Responsive Image Gallery, Gallery Album allows Stored XSS.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Mar 31, 2024

CVE-2024-31120 on NVD →

Responsive Image Gallery, Gallery Album <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitra...

CVSS:
6.4
Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Mar 29, 2024

CVE-2024-31120 on NVD →

Responsive Image Gallery, Gallery Album <= 2.0.3 - Reflected Cross-Site Scripting

medium

The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Mar 29, 2024

CVE-2024-30550 on NVD →

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)

unknown

[en] Unauth. Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Oct 18, 2023

CVE-2023-45630 on NVD →

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] <= 2.0.3 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.

Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Oct 16, 2023

CVE-2023-45629 on NVD →

Responsive Image Gallery, Gallery Album <= 2.0.3 - Unauthenticated Cross-Site Scripting

medium

The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...

CVSS:
6.1
Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Oct 11, 2023

CVE-2023-45630 on NVD →

Responsive Image Gallery, Gallery Album <= 2.0.3 - Missing Authorization via Multiple AJAX Actions

medium

The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to missing capability checks on multiple AJAX functions in versions up to, and including, 2.0.3. This makes it possible for authenticated attackers, with subscriber-level access and a...

CVSS:
5.4
Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Oct 11, 2023

CVE-2023-45631 on NVD →

Responsive Image Gallery, Gallery Album <= 2.0.3 - Cross-Site Request Forgery

medium

The Responsive Image Gallery, Gallery Album plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.3. This is due to missing or incorrect nonce validation multiple functions. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged...

CVSS:
5.4
Affected:
up to 2.0.3
Fix:
No patched version reported
Disclosed:
Oct 11, 2023

CVE-2023-45629 on NVD →

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] < 2.0.2 (closed)

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.1 versions.

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Mar 29, 2023

CVE-2022-47603 on NVD →

Gallery – Image and Video Gallery with Thumbnails <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting

high

The Responsive Image and video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$_GET["id"]’ parameter in versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

CVSS:
7.2
Affected:
up to 2.0.1
Fixed in:
2.0.2
Disclosed:
Feb 3, 2023

CVE-2022-47603 on NVD →

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] < 2.0.0 (closed)

unknown

[en] The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Jul 4, 2022

CVE-2022-1946 on NVD →

Gallery – Image and Video Gallery with Thumbnails <= 1.9.9 - Reflected Cross-Site Scripting

medium

The Gallery – Image and Video Gallery with Thumbnails plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.9 due to insufficient input sanitization and output escaping on the gallery_current_index parameter supplied via the wp_ajax_wpda_gall_load_image_info AJAX act...

CVSS:
6.1
Affected:
up to 1.9.9
Fixed in:
2.0.0
Disclosed:
Jun 13, 2022

CVE-2022-1946 on NVD →

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] < 1.2.1 (closed)

unknown

[en] SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Sep 25, 2017

CVE-2017-14125 on NVD →

Gallery &#8211; Image and Video Gallery with Thumbnails [gallery-album] < 1.2.1 (closed)

unknown

Authenticated SQL Injection vulnerability found by Manuel García Cárdenas in WordPress Responsive Image Gallery, Gallery Album version 1.2.0 and earlier versions.<br /> Update the Responsive Image Gallery, Gallery Album plugin to the latest available version (at least 1.2.1).<br />

Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Sep 25, 2017

Gallery – Image and Video Gallery with Thumbnails < 1.2.1 - SQL Injection

critical

SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.

CVSS:
9.8
Affected:
up to 1.2.1
Fixed in:
1.2.1
Disclosed:
Sep 22, 2017

CVE-2017-14125 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database